Source hostname instead of source_ip

Hello, is there any way to have a source_hostname instead of source_ip. I am looking to monitor traffic data and it seems there is only a choice by IP but hostname would be more useful since we wouldn't have to keep track of every IP.


Are you referring to the monitoring module that comes with X-Pack?

no packetbeat,

i would like to use hostnames instead of IP's

What hostname would you like to see? What protocols are you talking about here?

There is a reverse lookup filter in Logstash that can add hostnames to events.

how can this be done through logstash? is there a way to do this through elasticsearch as i am not sending any packetbeats to logstash.

You need Logstash for that. See

ok, ill give this a shot thanks!

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.